CVE-2026-29954

In KubePlus 4.1.4, the mutating webhook and kubeconfiggenerator components have an SSRF vulnerability when processing the chartURL field of ResourceComposition resources. The field is only URL-encoded without validating the target address. More critically, when kubeconfiggenerator uses wget to download charts, the chartURL is directly concatenated into the command, allowing attackers to inject wget's `--header` option to achieve arbitrary HTTP header injection.
References
Link Resource
https://gist.github.com/b0b0haha/33baea60fd2a847f11f1fb02e43c64c0 Exploit Mitigation Third Party Advisory
https://github.com/b0b0haha/CVE-2026-29954/blob/main/README.md Exploit Mitigation Third Party Advisory
Configurations

Configuration 1 (hide)

cpe:2.3:a:cloudark:kubeplus:4.1.4:*:*:*:*:*:*:*

History

No history.

Information

Published : 2026-03-30 17:16

Updated : 2026-06-17 10:29


NVD link : CVE-2026-29954

Mitre link : CVE-2026-29954

CVE.ORG link : CVE-2026-29954


JSON object : View

Products Affected

cloudark

  • kubeplus
CWE
CWE-88

Improper Neutralization of Argument Delimiters in a Command ('Argument Injection')

CWE-918

Server-Side Request Forgery (SSRF)